GDPR & Data Processing

Last updated: April 7, 2026

1. Scope

This policy applies to users located in the European Union (EU) and European Economic Area (EEA), and to the processing of personal data of EU/EEA data subjects, in accordance with the General Data Protection Regulation (GDPR).

NeoRosetta acts as a data controller for personal data collected through the Entelligence platform.

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contractual necessity: Processing required to provide the platform services you have signed up for (account management, service delivery)
  • Legitimate interest: Platform security, fraud prevention, service improvement, and analytics
  • Consent: Where you have given explicit consent, such as connecting third-party integrations
  • Legal obligation: Where processing is required to comply with applicable laws

3. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to restrict processing: Request that we limit how we use your data
  • Right to object: Object to processing based on legitimate interest
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

4. International Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA, including:

  • Australia: Where NeoRosetta is headquartered and where platform infrastructure is located
  • United States: Where our AI providers (OpenAI and Anthropic) process data to deliver AI-powered features

For transfers outside the EU/EEA, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data receives an adequate level of protection.

5. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in our Privacy Policy:

  • Account data: Retained while your account is active and for 30 days after deletion
  • Usage data: Retained in aggregated form for up to 24 months
  • Uploaded content: Deleted within 30 days of account deletion or upon your request

6. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments
  • Employee training on data protection

7. Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all third-party processors who handle personal data on our behalf, including our AI providers and infrastructure partners. These agreements ensure processors meet GDPR requirements for data protection.

8. Data Protection Contact

For GDPR-related inquiries or to exercise your data subject rights:

Data Protection Officer:
Email: [email protected]
Company: NeoRosetta
Location: Australia

9. Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement.

10. Changes to This Policy

We may update this GDPR policy from time to time. Changes will be posted on this page with a revised "Last updated" date. We will notify affected users of material changes.